CVE-2024-1930: No Limit on Number of Open Sessions / Bad Session Close Behaviour
Published Mar 4, 2024
·Updated
No Limit on Number of Open Sessions / Bad Session Close Behaviour
Affected Software
6 affected componentsFixes available
dnf5 dnf5daemon-server<5.1.17
Rpm-software-management Dnf5<5.1.17
Microsoft cbl2 dnf5 5.0.14-3
Microsoft cbl2 dnf5 5.0.14-2
Microsoft azl3 dnf5 5.1.11-2
Microsoft azl3 dnf5 5.1.11-3
Event History
May 8, 2024
CVE Published
via MITRE·01:52 AM
Data Sourced
via MITRE·01:52 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Sep 4, 2025
Data Sourced
via Microsoft·02:32 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:32 AM
Affected Software
Updated
via Microsoft·02:32 AM
SeverityAffected Software
Updated
via Microsoft·02:32 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-1930?
CVE-2024-1930 is considered a medium severity vulnerability due to its potential impact on the availability of the affected system.
2
How do I fix CVE-2024-1930?
To fix CVE-2024-1930, upgrade the dnf5daemon-server to version 5.1.17 or later.
3
What does CVE-2024-1930 affect?
CVE-2024-1930 affects the dnf5daemon-server prior to version 5.1.17 by allowing an unlimited number of open sessions.
4
What is the main issue caused by CVE-2024-1930?
The main issue caused by CVE-2024-1930 is the potential denial of service due to the lack of limits on open sessions.
5
Who is impacted by CVE-2024-1930?
Any users or systems utilizing dnf5daemon-server versions before 5.1.17 are impacted by CVE-2024-1930.